CVE-2012-6123: Input Validation
Published Oct 31, 2019
·Updated
Chicken before 4.8.0 does not properly handle NUL bytes in certain strings, which allows an attacker to conduct "poisoned NUL byte attack."
Affected Software
5 affected componentsFixes available
debian/chicken
5.2.0-25.3.0-15.3.0-2
Call-cc Chicken<4.8.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Event History
Oct 31, 2019
CVE Published
via MITRE·08:38 PM
Data Sourced
via MITRE·08:38 PM
DescriptionWeakness
Aug 6, 2024
Data Sourced
via Debian·09:34 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2012-6123?
CVE-2012-6123 is classified as a medium severity vulnerability due to the potential for a poisoned NUL byte attack.
2
How do I fix CVE-2012-6123?
To mitigate CVE-2012-6123, upgrade to Chicken version 4.8.0 or later, or install the patched versions available in Debian packages 5.2.0-2 or 5.3.0-1.
3
What impact does CVE-2012-6123 have on affected systems?
CVE-2012-6123 can allow attackers to conduct a poisoned NUL byte attack, potentially compromising the integrity of the application's data handling.
4
Which versions of Chicken are affected by CVE-2012-6123?
CVE-2012-6123 affects all versions of Chicken prior to 4.8.0.
5
Is CVE-2012-6123 related to specific operating systems?
CVE-2012-6123 is primarily associated with Debian Linux versions 8.0, 9.0, and 10.0 containing affected Chicken packages.